Electronic identity card general information

Where can I obtain an electronic identity card?

The application for an electronic identity card can be filed in person at an administrative unit in the Republic of Slovenia or at diplomatic representations and consular posts of the Republic of Slovenia abroad.
Children under the age of 12 are issued with an identity card that is not electronic but has a chip with biometric data. After the child reaches the age of 12, the chip also contains the qualified certificate for electronic signature and means of electronic identification of high and low assurance levels.

What is the validity of the electronic identity card?

The electronic identification and the qualified certificate for electronic signature have the same validity as the identity card for persons above the age of 12. 
For persons aged 12 to 18, the validity is 5 years, 
and for persons aged 18 to 70, the validity is 10 years. 
The exception is the identity card with permanent validity (issued to a citizen who filed the application for the issue of the identity card after the age of 70); in this case, the electronic identification and the qualified certificate for electronic signature are valid for 10 years from the date of issue of the identity card, while the validity of the identity card used for physical identification is permanent.

What does it contain and for what purpose can I use the electronic identity card?/h3>

  • The electronic identification means of low assurance level can be used when logging into web applications for which a high level of identification is not required (e.g. online store); application in the health insurance system (being prepared).
  • 
The electronic identification means of high assurance level is used when logging into web applications (e.g. eGovernment, zVEM, eDavki, Spot, etc.).
  • 
The qualified certificate for electronic signature is used for electronic signing (used in signature tools, e.g. Adobe Reader, etc.).

Do I have to activate the electronic section of the identity card, or can I use the card only as an identification and travel document

The electronic identity card must only be activated if you wish to use the digital certificate for electronic signature and the digital certificate of high assurance level for logging into various web applications.

I have lost my identity card. How do I revoke the electronic identity card or digital certificates on the identity card?

The application for temporary suspension can be submitted electronically on the website. The application is submitted with the use of the electronic identification means of at least substantial assurance level (e.g. smsPASS).
Temporary suspension lasts no more than 48 hours. During this time, the digital certificates on the electronic identity card are unavailable and are placed on the list of revoked digital certificates. If the temporary revocation requested in person at an administrative unit is not withdrawn in this period, the electronic identity card is cancelled automatically.

Can I cancel the electronic identity card?

If you decide that you no longer wish to use the electronic identity card, you can submit an oral request for cancellation of the electronic identity card at an administrative unit or a diplomatic/consular representation. The biometric identity card remains valid and can be further used for proving your identity.
After the receipt of the request for cancellation, SI-TRUST will cancel the certificate within two hours at the latest. 
By cancelling the electronic identity card, you also cancel all three digital certificates on the electronic identity card (digital certificate of high assurance level, digital certificate of low assurance level and digital certificate for electronic signature).

What do I do if the chip is damaged?

Apply for a new identity card.

Can I make a backup copy of the electronic identity card?

It is not possible to make a backup copy.

What is the purpose of the QR code (barcode in the form of an abstract black and white diagram)?

It enables the verification of validity of the identity card on the eGovernment portal and thus enhances legal security (validity may be checked by notaries, banks, insurance companies and others in Slovenia and abroad).

What are the security parameters?

Two methods are used for the protection of digital certificates of high and low assurance levels and the qualified certificate for electronic signature:

  • Access to the digital certificate of low assurance level is possible without the application of security parameters and is enabled between the identity card, the smart card reader and the CAN code during a contactless use of the electronic identity card.
 The data from the chip can be read through the NFC protocol with a simultaneous entry of the CAN code, which is printed vertically in the lower right corner on the front side of the identity card, and the entry of the PIN code or a user password for reading the digital certificate of high assurance level and the digital certificate for electronic signature.
  • The PIN code or user password is used for the requirements of the electronic identification means of high assurance level and the qualified certificate for electronic signature.

What about abuse? Is it possible to read the chip through the NFC protocol?

The data on the chip can only be read via the NFC protocol with a simultaneous entry of the CAN code, which is printed vertically in the lower right corner on the front side of the identity card. The digital certificate of high assurance level and the digital certificate for electronic signature are additionally protected with a PIN code.

Which hardware is required for the use of the eID card?

When using eOsebna mobile application:

  • smartphone that supports the NFC technology and Android or iOS operating system (operating was tested for iPhone 8 and upwards),
  • use is possible directly on a smartphone or in combination with another device, e.g. tablet or computer.

When using the eID card in combination with a smart card reader:

  • computer with the Windows operating system (Win 10 64 bit) or the Mac operating system (from v.10.15 (Catalina) upwards),
  • smart card reader.

Setting of the PIN code or activation of the electronic identity card

How do I set up the PIN code or activate the electronic identity card?

It is possible to activate or set up the PIN code in two ways:

  • with the eOIActivator software,
  • with the eOsebna mobile application.

Why do I have to activate the electronic identity card? 

The eID card has to be activated for the use of digital certificates that are protected with a password. These are the digital certificate for electronic signature and the digital certificate of high assurance level. 

Can I use the electronic identity card if I do not activate it? 

The digital certificate of low assurance level, which is not protected by the PIN code, can be used with the inactivated eID card. 

If I want to use the identity card for identification purposes in healthcare instead of the health insurance card, do I have to activate it first?

The activation or setting up of the PIN code is not necessary in this case, as the digital certificate of low assurance level, which is not protected by the PIN code, is used for the identification purposes in healthcare. 

CAN code

What is the CAN code?

CAN is the acronym for Card Access Number and enables access to digital certificates on an electronic identity card in contactless use of the identity card. The CAN code consists of six digits that are printed vertically in the lower right corner on the front side of the identity card.

Where is the CAN code?

The CAN code is printed on the identity card and consists of six digits that are printed vertically in the lower right corner on the front side of the identity card. 

kodaCan

Initial password

When and how do I get the initial password?

You will receive the initial password by mail several days after the receipt of the identity card. If you collect the identity card from the administrative unit in person, the initial password is already in the envelope together with the identity card. 

Why do I need the initial password?

The initial password is needed to set up the PIN code or to activate the identity card. The PIN code is your user password. Once the PIN code is set up, the initial password will no longer be applicable, and you can dispose of it. 

I have not received the initial password.

If you ordered the identity card by mail, you should have received the initial password sent to your address by regular mail several days later. Check at the post office for lost mail. If the envelope with the initial password is lost, you can use the PUK code to set up the PIN code for activation of the identity card. To obtain the PUK code, you must visit an administrative unit or a diplomatic/consular representation and submit an oral request.

I have lost the initial password. 

The initial password cannot be sent again. If you have not yet activated your eID card or set up the PIN code, you must visit an administrative unit or a diplomatic/consular representation to submit an oral request to obtain the PUK code or the code for resetting the password. 

PIN code or user password

Why do I need a PIN code or a user password?

The PIN code or the user password is used every time you use electronic identification of high assurance level to login into e-services or when you want to electronically sign a document by means of the qualified digital certificate for electronic signature.

Where should I save the PIN code or the user password?

Memorise the PIN code or the user password and do not share it with anyone. If you save the PIN code, save it in a secure place that is not accessible to unauthorised persons. For safety reasons, do not save the PIN code on a smart device.

What happens if I forget the PIN code or the user password?

If you forget the PIN code and the electronic identity card is locked after six unsuccessful attempts to enter the PIN code, you will need the PUK code or the code for resetting the user password to unlock the electronic identity card. To obtain the PUK code, visit an administrative unit or a diplomatic/consular representation.

Why should I not share my PIN code or user password with other people? 

The PIN code serves as protection so that other unauthorised persons cannot use your digital certificate of high assurance level to login into e-services and your digital certificate for e-signature, which are saved on your eID card. If you share your PIN code with other people, you risk them interfering with your data and possibly abusing it. 

Can I set up two different PIN codes for the digital certificate for e-signature and the digital certificate of high assurance level? 

The PIN code is the same for both certificates, so you cannot set up different PIN codes for individual certificates. 

How do I change the PIN code? 

The PIN code can be changed with the IDProtect Client software or through the eOsebna mobile application.

PUK code or code for resetting the user password

What is the PUK code? 

The PUK code is intended for resetting the PIN code or the user password. Handle the PUK code with due care, as it cannot be changed and stays the same throughout the entire validity period of the eID card.

Where do I obtain the PUK code?

To obtain the PUK code, visit an administrative unit or a diplomatic/consular representation. You will receive the envelope with the PUK code by registered mail to your address for service in a few days after you have submitted the oral request to obtain the code for resetting the user password or the PUK code. 

Where should I save the PUK code? 

We recommend that you do not save the PUK code but obtain it every time you need it. If you save the PUK code, save it in a secure place that is not accessible to unauthorised persons. 

What happens if I enter an incorrect PUK code? 

After ten unsuccessful attempts, the PUK code will be locked. Once the PUK code is locked, it cannot be unlocked. If your eID card locks after ten incorrect entries of the PUK code, you will have to obtain a new identity card to further use e-services with the electronic identity card.

Can I lock the electronic identity card?

You can lock the electronic identity card if you enter an incorrect PIN code or the user password six times. The electronic identity card is fully locked after ten incorrect entries of the PUK code. A fully locked eID card cannot be unlocked.

The electronic identity card has been locked. 

Visit an administrative unit or a diplomatic/consular representation to submit an oral request to obtain the PUK code or the code for resetting the password of the electronic identity card. You will receive an envelope containing the PUK code by registered mail to your address for service in a few days. 

How to reset the PIN code? 

The PIN code can be reset with the PUK code by means of the IDProtect Client software or through the eOsebna mobile application.

Mobile application

Can I only use the eID card with the eOsebna mobile application, and in which services can I log in via the mobile application with the electronic identity card?

The mobile application enables the login into e-services, which use the SI-PASS service for logging, and the management of passwords of the eID card. Via the eOsebna mobile application, it is possible to activate the eID card, change the PIN code, unlock the eID card with the PUK code, and review data on the identity card.

How can I use the mobile application?

When logging into e-services, the mobile application is used as a smart card reader. It may be used in two ways: directly on a smartphone or in combination with another device, e.g. tablet or computer:

  • use of e-services on the smartphone on which the mobile application is installed. The user starts the e-service process on the website of the e-service provider and is then redirected to the mobile application during the authentication process with an electronic identity card. They then follow the procedure of entering the PIN code and reading of the electronic identity card through the NFC protocol. After successful authentication, users are logged in and can continue the implementation of e-service in the browser of their phone;
  • use of e-services on another device, e.g. tablet or computer. Users start the procedure of e-service on the website of the e-service provider on their computer or tablet and select login via a mobile application and eID card when selecting a suitable login method. A QR code is displayed. Users then open the mobile application on their smartphones, with which they scan the QR code and follow the procedure of entering the PIN code in the mobile application and reading the electronic identity card through the NFC protocol. After successful authentication, users are logged in and can continue the implementation of e-service, for example, on their tablet or computer.

On which smart devices does the eOsebna application work, and is it available in Google Play and App Store?

The eOsebna mobile application works on smart devices with Android or iOS operating system (operating was tested for iPhone 8 and upwards), which support the NFC protocol and are available in Google Play and App Store.

Does every person in a family require their own smartphone to use the eOsebna mobile application?

The mobile application can be used for a random number of electronic identity cards. One suitable smartphone in a family suffices for the use of the mobile application.

Software for the use of eID card with a smart card reader

Which hardware is required for the use of the eID card?

When using the eID card in combination with the smart card reader: 

  • computer with the Windows operating system (Win 10 64 bit) or the Mac operating system (from v.10.15 (Catalina) upwards), 
  • smart card reader.

Which software do I need to use the electronic identity card with a smart card reader?

The eOIActivator programme is needed for the first setup of the PIN code. Prior to the first use of the electronic identity card, the PIN code must be set up with the help of the initial password or the PUK code if you do not have access to the initial password. 
For further use of the eID card, the IDProtect Client programme is needed. The IDProtect Client programme is used for reading digital certificates installed on your eID card. The IDProtect Client programme is used to change the PIN code and unlock the eID card with the PUK code. 

What is the function of the IDProtect Client programme?

The IDProtect Client is the software needed for reading digital certificates installed on your eID card. The IDProtect Client programme is used to change the PIN code and unlock the eID card with the PUK code. 

How do I activate the electronic identity card with the use of the smart card reader?

Prior to the first use of the electronic identity card, the PIN code must be set up with the help of the initial password or the PUK code if you do not have access to the initial password. When using the eID card in combination with the smart card reader: The eOIActivator programme is needed for the first setup of the PIN code.

Smart card readers

What is a smart card reader? 

A smart card reader is a peripheral device that enables the reading of data from the chip of a smart card. Smart card readers are either contact readers enabling contact between the chip and the reader’s circuit or contactless readers where a smart card or an identity card must be placed on, or brought closer to, the reader.